CVE-2024-7570
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2024-7570 is a newly disclosed vulnerability affecting Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier. This issue involves improper certificate validation, allowing a remote attacker in a Man-in-the-Middle (MITM) position to craft a token that grants unauthorized access to ITSM as any user. Successful exploitation of this vulnerability can lead to significant security risks, including unauthorized access to sensitive data and potential privilege escalation. Ivanti urges users to update their systems as soon as possible to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.